CVE Tools

Google Chrome

6,611 CVEs tracked. 77 of them are in CISA KEV.

This hub aggregates every CVE we track for Google Chrome, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Google Chrome CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Google Chrome CVEs per month
MonthCVEs
2024-1022
2024-1113
2024-127
2025-0117
2025-029
2025-0316
2025-0413
2025-0514
2025-0610
2025-076
2025-0816
2025-0912
2025-101
2025-1167
2025-1219
2026-0112
2026-0220
2026-0374
2026-04144
2026-05370
2026-06965
2026-07487
2026-08396
2026-09326

Severity

How the 6,611 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical6099%
  • High3,04046%
  • Medium2,81943%
  • Low1432%

Latest CVEs

The 15 most recently published vulnerabilities affecting Google Chrome.

  1. CVE-2026-93386UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium securi...5.4
  2. CVE-2026-93385Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)6.5
  3. CVE-2026-93378Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromiu...3.1
  4. CVE-2026-93377Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium ...8.8
  5. CVE-2026-93384Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted...3.7
  6. CVE-2026-93380Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access rest...3.1
  7. CVE-2026-93383Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)4.3
  8. CVE-2026-93376Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium s...6.3
  9. CVE-2026-93387Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)4.3
  10. CVE-2026-93381Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via ...8.8
  11. CVE-2026-93373Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security sever...9.6
  12. CVE-2026-93379Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)4.3
  13. CVE-2026-93375Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local progra...8.1
  14. CVE-2026-93382Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8.8
  15. CVE-2026-93372Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security se...9.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store